Skip to main content

Use case · Salesforce platform teams

Scheduled security scans for every Salesforce org.

A platform team owns more orgs than anyone can audit by hand. Vulkro Cloud scans each of them on a schedule you set, keeps every result, and opens on the short list of what to fix first.

Vulkro Cloud · Vulkro for Salesforce · VS Code extension

acme.vulkro.comWorkspace · 4 orgs
Posture81/100+9 since last scan
Open issues376 fixed · 2 new
Attack paths31 reaches personal data
Fix firstranked by reach and severity
  1. 1VK-214Guest user reads Invoice__c.Bank_Account__cAttack pathCritical
  2. 2VK-188Integration user holds Modify All DataIdentityHigh
  3. 3VK-231Connected app allows all users, no IP rangeExposureHigh
  4. 4VK-097Session timeout above 2 hours on admin profileSettingsMedium
Changes5 Oct compared with 28 Sep: 6 fixed, 2 new, 1 reopened

01The problem

Org access changes between yearly audits

Access in Salesforce drifts through everyday admin work, long after the last review signed it off.

  • Change outside code

    A permission set, a sharing rule or a connected app is changed in Setup, not in a pull request. Nothing reviews it.

  • Sandboxes drift

    Sandboxes and production stop matching, and a fix made in one never reaches the other.

  • Findings lists with no history

    A findings list from each org, each run, with no memory of what was fixed or accepted last time.

  • Issues have no owner

    An issue with no owner, no status and no history is an issue that comes back.

03The workflow

Steps from first scan to fix

  1. 01

    Connect your orgs

    Add production, sandboxes and Experience Cloud orgs to your workspace. Scans read settings and metadata, never your records.

    Vulkro Cloud
  2. 02

    Set the schedule

    Daily, weekly or monthly per org, with a quiet window so no scan starts during a release.

    Vulkro Cloud
  3. 03

    Work through Fix first

    Open issues ranked by severity, each with the attack path behind it. Assign an owner and route it to Jira or chat.

    Vulkro Cloud
  4. 04

    Fix in the editor

    The developer opens the class, sees the finding on the line and fixes it with the explanation in front of them.

    VS Code extension
  5. 05

    The rescan closes fixed issues

    The next scheduled scan no longer finds the issue and marks it fixed. If it comes back, it is reopened.

    Vulkro Cloud

04What you get

What you get

Coverage
Every live org on its own schedule, scanned in parallel.
Change
After two complete scans, Changes shows what is new, what was fixed and what came back.
Priority
Fix first: open issues by severity, with the path that makes each one matter.
Accountability
An accepted risk or false positive stays counted until a second person approves it.
Access
Roles from Owner to Auditor and Viewer, scoped per org, or roles of your own.

Questions

Common questions

Does Vulkro Cloud read our customer records?
No. Scans read settings and metadata. Each company gets its own workspace with its own database, storage and keys, and each scan runs in an isolated container.
Can we try it today?
Vulkro Cloud is available by invitation. Request access and we reply within two business days. Meanwhile Vulkro for Salesforce scans your DX project on your own machine, free.
Does Vulkro Cloud change anything in our orgs?
No. Vulkro reports and proposes fixes as Setup paths and metadata changes. It never deploys or applies a fix.
Can we add our own policies?
Yes. Write custom rules on users, permission sets, integrations, Health Check settings or Apex, and test them on the latest scan before they go live.

Scan every Salesforce org on a schedule.